US2023267067A1PendingUtilityA1

Software protection from attacks using self-debugging techniques

Assignee: NAGRAVISION SAPriority: Nov 27, 2017Filed: Apr 26, 2023Published: Aug 24, 2023
Est. expiryNov 27, 2037(~11.3 yrs left)· nominal 20-yr term from priority
G06F 11/3624G06F 8/447G06F 9/4856G06F 11/3636G06F 11/3644
65
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In overview, methods, computer programs products and devices for securing software are provided. In accordance with the disclosure, a method may comprise attaching a debugger process to a software process. During execution of the software process, operations relevant to the functionality of the code process are carried out within the debugger process. As a result, the debugger process cannot be replaced or subverted without impinging on the functionality of the software process. The software process can therefore be protected from inspection by modified or malicious debugging techniques.

Claims

exact text as granted — not AI-modified
1 . A method of generating protected code, comprising:
 identifying one or more functions in code to be compiled for a first process to be migrated to a second process, wherein the one of the first and second processes is a debugger for the other of the first and second processes;   migrating the identified function or functions to the second process;   modifying the first process to allow transfer of state between the first and second processes; and   compiling the first and second processes to generate binary code.   
     
     
         2 . A method according to  claim 1 , wherein the code to be compiled is source code or bitcode. 
     
     
         3 . A method according to either  claim 1  or  claim 2 , further comprising injecting an initializer into one of the first and second processes to invoke execution of the other of the first and second processes. 
     
     
         4 . A method according to any one of the preceding claims, further comprising injecting one or more initializers into the first or second processes to register functions present in the other of the first and second process. 
     
     
         5 . A method according to any one of the preceding claims, wherein each of the first and second processes is a debugger for the other of the first and second processes. 
     
     
         6 . A method according to any one of the preceding claims, further comprising providing a third process which is a debugger for one of the first and second processes. 
     
     
         7 . A computer executable program product comprising computer executable code for carrying out the method of any one of the preceding claims. 
     
     
         8 . A device configured to carry out the method of any one of  claims 1  to  6 . 
     
     
         9 . A method for securing software, comprising:
 launching a software process;   attaching a debugger process to the software process;   executing the software process such that the debugger process is invoked at least once;   performing one or more functions within the debugger process in response to invocation of the debugger process, the one or more functions having an output dependent on data associated with the software process,   wherein the software process generates a data structure comprising parameters required for performance of the one or more functions within the debugger process prior to invocation of the debugger process.   
     
     
         10 . A method according to  claim 9 , wherein the output comprises a data output for use by the software process. 
     
     
         11 . A method according to  claim 9  or  claim 10 , wherein the data structure is a state structure. 
     
     
         12 . A method according to any one of  claims 9  to  11 , wherein the software process acts to debug the debugger process. 
     
     
         13 . A method according to any one of  claims 9  to  12 , further comprising launching an additional process to debug the debugger process. 
     
     
         14 . A method according to any one of  claims 9  to  13 , wherein the output of a given function may indicate multiple points of return within the software process for continued execution. 
     
     
         15 . A method according to any one of  claims 9  to  14 , wherein the debugger process provides memory support capabilities to enable the one or more functions to retrieve data from memory within address space of the software process. 
     
     
         16 . A method according to any one of  claims 9  to  15 , wherein the debugger process is invoked when a break point within the software process is reached. 
     
     
         17 . A method according to any one of  claims 9  to  16 , further comprising detaching the debugger process from the software process when the software process is complete. 
     
     
         18 . A method according to any one of  claims 9  to  17 , wherein the software process implements an executable, such as an application. 
     
     
         19 . A method according to any one of  claims 9  to  17 , wherein the software process implements a library. 
     
     
         20 . A computer executable program product comprising computer executable code for carrying out the method of any one of  claims 9  to  19 . 
     
     
         21 . A device configured to carry out the method of any one of  claims 9  to  19 .

Join the waitlist — get patent alerts

Track US2023267067A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.